Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so called gadget chain presents no direct threat, but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability.
We have discovered 103,755 live websites that are affected by CVE-2024-55636.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 103,755 live websites (50% of Drupal install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 247 versions ( 73% of all versions) |
| 36,673 websites | |
| 9,934 websites | |
| 7,976 websites | |
| 5,003 websites | |
| 3,973 websites | |
| 3,576 websites | |
| 3,279 websites | |
| 2,840 websites | |
| 2,579 websites | |
| 2,363 websites |
| .com | 27,352 websites |
| .org | 9,897 websites |
| .de | 6,443 websites |
| .edu | 6,410 websites |
| .be | 4,990 websites |
| .fr | 4,478 websites |
| .nl | 3,223 websites |
| .ru | 2,600 websites |
| .ca | 2,087 websites |
| .it | 2,010 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***.**.uk | *** | ||
| *********.com | *** | ||
| ***.gov | *** | ||
| *******.gov | *,*** | ||
| ***.gov | *,*** | ||
| ***.gov | *,*** | ||
| ******.com | *,*** | ||
| *******.com | *,*** | ||
| ***.org | *,*** | ||
| ***.*******.edu | *,*** |
FAQ